Skip to content

Security: Establish Bug Bounty Program & SECURITY.md #96

@AlAfiz

Description

@AlAfiz

Description

White-hat hackers need a safe, formal way to report vulnerabilities without dropping 0-days in the public GitHub issues.

Acceptance Criteria

  • Create a SECURITY.md file in the root of the monorepo.
  • Define the exact scope of the bug bounty (e.g., Soroban Contracts: In Scope, Next.js UI bugs: Out of Scope for payout).
  • Provide a secure contact method (e.g., a PGP key and security@yourdomain.com).
  • Define the SLA (Service Level Agreement) for how quickly the team will respond to reports.

Technical Details

  • Mention explicitly that any public disclosure before the team patches the vulnerability automatically voids the bounty.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions